H3C SR8800-F manuals
SR8800-F
Table of contents
- obtaining documentation
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Table Of Contents
- Configuring AAA
- RADIUS
- HWTACACS
- LDAP
- User management based on ISP domains and user access types
- AAA for MPLS L3VPNs
- AAA tasks at a glance
- Configuring local users
- Local user configuration tasks at a glance
- Configuring attributes for network access users
- Configuring local guest attributes
- Configuring user group attributes
- Managing local guests
- Display and maintenance commands for local users and local user groups
- Configuring RADIUS
- Creating a RADIUS scheme
- Specifying the RADIUS accounting servers
- Specifying the shared keys for secure RADIUS communication
- Setting the username format and traffic statistics units
- Setting the maximum number of real-time accounting attempts
- Setting the maximum number of pending RADIUS requests
- Enabling the RADIUS server load sharing feature
- Specifying the source IP address for outgoing RADIUS packets
- Setting RADIUS timers
- Configuring the RADIUS accounting-on feature
- Configuring the Login-Service attribute check method for SSH, FTP, and terminal users
- Configuring the format for RADIUS attribute 87
- Specifying a server version for interoperating with servers with a vendor ID of 2011
- Configuring the RADIUS session-control feature
- Changing the DSCP priority for RADIUS packets
- Enabling SNMP notifications for RADIUS
- Configuring HWTACACS
- Specifying the HWTACACS authorization servers
- Specifying the HWTACACS accounting servers
- Specifying an MPLS L3VPN instance for the scheme
- Configuring HWTACACS stop-accounting packet buffering
- Setting HWTACACS timers
- Display and maintenance commands for HWTACACS
- Configuring LDAP
- Specifying the LDAP version
- Configuring LDAP user attributes
- Configuring an LDAP attribute map
- Specifying the LDAP authentication server
- Configuring AAA methods for ISP domains
- Configuring ISP domain attributes
- Configuring authentication methods for an ISP domain
- Configuring authorization methods for an ISP domain
- Configuring accounting methods for an ISP domain
- Display and maintenance commands for ISP domains
- Setting the maximum number of concurrent login users
- Display and maintenance commands for local bill cache
- Setting the NAS-ID on an interface
- Configuring the device ID
- Example: Configuring local authentication and authorization for SSH users
- Example: Configuring AAA for SSH users by an HWTACACS server
- Example: Configuring authentication for SSH users by an LDAP server
- Example: Configuring AAA for PPP users by an HWTACACS server
- Troubleshooting RADIUS
- RADIUS packet delivery failure
- Troubleshooting HWTACACS
- Appendixes
- Appendix B Descriptions for commonly used standard RADIUS attributes
- Appendix C RADIUS subattributes (vendor ID 25506)
- DHCP overview
- IP address allocation process
- DHCP message format
- DHCP options
- Vendor-specific option (Option 43)
- Relay agent option (Option 82)
- Protocols and standards
- Configuring the DHCP server
- Principles for selecting an address pool
- IP address allocation sequence
- Creating a DHCP user class
- Creating a DHCP address pool
- Specifying gateways for DHCP clients
- Specifying DNS servers for DHCP clients
- Specifying the configuration file for DHCP client auto-configuration
- Specifying a server for DHCP clients
- Configuring the DHCP user class whitelist
- Enabling the DHCP server on an interface
- Configuring a DHCP policy for dynamic address assignment
- Allocating different IP addresses to DHCP clients with the same MAC
- Enabling handling of Option 82
- Configuring the DHCP server security features
- Configuring DHCP starvation attack protection
- Configure the DHCP server to ignore BOOTP requests
- Configuring the DHCP server to send BOOTP responses in RFC 1048 format
- Configuring DHCP binding auto backup
- Advertising subnets assigned to clients
- Enabling client offline detection on the DHCP server
- Enabling DHCP logging on the DHCP server
- DHCP server configuration examples
- Example: Configuring dynamic IP address assignment
- Example: Configuring DHCP user class
- Example: Configuring DHCP user class whitelist
- Example: Configuring primary and secondary subnets
- Example: Customizing DHCP option
- Example: Configuring DHCP server (WLAN application)
- Procedure
- Configuring the DHCP relay agent
- DHCP relay agent support for Option 82
- DHCP relay agent tasks at a glance
- Specifying DHCP servers
- Specifying the DHCP server selecting algorithm
- Configuring the DHCP relay agent security features
- Configuring DHCP flood attack protection
- Enabling DHCP server proxy on the DHCP relay agent
- Enabling client offline detection on the DHCP relay agent
- Setting the DSCP value for DHCP packets sent by the DHCP relay agent
- Configuring DHCP packet rate limit on a DHCP relay interface
- Specifying the source IP address for DHCP requests
- Configuring the DHCP relay agent to always unicast relayed DHCP responses
- Display and maintenance commands for DHCP relay agent
- DHCP relay agent configuration examples
- Example: Configuring Option 82
- Troubleshooting DHCP relay agent configuration
- Configuring the DHCP client
- Enabling duplicated address detection
- Display and maintenance commands for DHCP client
- enable dhcp
- Configuring DHCP snooping
- DHCP snooping support for Option 82
- Restrictions and guidelines: DHCP snooping configuration
- Configuring Option 82
- Configuring DHCP snooping entry auto backup
- Enabling DHCP starvation attack protection
- Setting the maximum number of DHCP snooping entries
- Enabling DHCP snooping logging
- DHCP snooping configuration examples
- Example: Configuring DHCP snooping support for Option 82
- Configuring the BOOTP client
- Display and maintenance commands for BOOTP client
- DHCPv6 overview
- Address/prefix lease renewal
- Stateless DHCPv6
- Option 37
- Configuring the DHCPv6 server
- Concepts
- IPv6 address/prefix allocation sequence
- DHCPv6 server tasks at a glance
- Configuring IPv6 address assignment
- Configuring network parameters assignment
- Configuring network parameters in a DHCPv6 address pool
- Configuring a DHCPv6 policy for IPv6 address and prefix assignment
- Configuring the DHCPv6 server on an interface
- Allocating different IPv6 addresses to DHCPv6 clients with the same MAC
- Configuring DHCPv6 binding auto backup
- Applying a DHCPv6 address pool to a VPN instance
- Configuring the DHCPv6 server security features
- Enabling the DHCPv6 server to advertise IPv6 prefixes
- DHCPv6 server configuration examples
- Example: Configuring dynamic IPv6 address assignment
- Configuring the DHCPv6 relay agent
- DHCPv6 relay agent tasks at a glance
- Specifying DHCPv6 servers for a DHCPv6 address pool on the DHCPv6 relay agent
- Specifying a gateway address for DHCPv6 clients
- Specifying a padding mode for the Interface-ID option
- Enabling client offline detection
- Enabling the DHCPv6 relay agent to advertise IPv6 prefixes
- DHCPv6 relay agent configuration examples
- Configuring DHCPv6 snooping
- Restrictions and guidelines: DHCPv6 snooping configuration
- Configuring support for Option 18
- Setting the maximum number of DHCPv6 snooping entries
- Configuring a DHCPv6 packet blocking port
- Display and maintenance commands for DHCPv6 snooping
- Configuring MAC authentication
- Authentication methods
- ACL assignment
- Periodic MAC reauthentication
- Prerequisites for MAC authentication
- Configuring the user account format
- Enabling MAC authentication offline detection
- Configuring MAC authentication delay
- Prerequisites
- Including user IP addresses in MAC authentication requests
- MAC authentication configuration examples
- Example: Configuring RADIUS-based MAC authentication
- Example: Configuring ACL assignment for MAC authentication
- ftp server
- Configuring PPP
- PPP authentication
- PPP for IPv6
- Configuring PPP authentication
- Configuring CHAP authentication (authenticator name is configured)
- Configuring CHAP authentication (authenticator name is not configured)
- Configuring MS-CHAP or MS-CHAP-V2 authentication
- Configuring the polling feature
- Enabling fast reply for keepalive packets
- Configuring IP address negotiation on the client
- Enabling IP segment match
- Configuring DNS server IP address negotiation on the client
- Enabling logging for PPP users
- Enabling PPP user blocking
- Suppressing adding PPP peer host routes to the local direct route table
- Configuring L2TP
- L2TP tunnel and session
- L2TP features
- L2TP-based EAD
- L2TP tasks at a glance
- Configuring basic L2TP capabilities
- Specifying LNS IP addresses
- Enabling transferring AVP data in hidden mode
- Configuring an LNS
- Creating a VT interface
- Configuring AAA authentication on an LNS
- Setting the Hello interval
- Enabling L2TP-based EAD
- Display and maintenance commands for L2TP
- Example: Configuring a client-initiated L2TP tunnel
- Example: Configuring an LAC-auto-initiated L2TP tunnel
- Troubleshooting L2TP
- Data transmission failure
- Configuring PPPoE
- Host-initiated network structure
- Configuring the PPPoE server
- Setting the maximum number of PPPoE sessions
- Configuring the NAS-Port-ID attribute
- Enabling PPPoE users to come online despite the PPPoE-NAT444 collaboration failure
- Setting the maximum number of PADI packets that the device can receive per second
- Enabling PPPoE logging
- PPPoE configuration examples
- Example: Assigning the PPPoE server IP address through the local DHCP server
- Example: Assigning the PPPoE server IP address through a remote DHCP server
- Example: Assigning the PPPoE server IPv6 address through ND and IPv6CP negotiation
- Example: Assigning the PPPoE server IPv6 address through DHCPv6
- Example: Assigning the PPPoE server IPv6 address through prefix delegation by DHCPv6
- Example: Configuring PPPoE server RADIUS-based IP address assignment
- Configuring portal authentication
- Portal authentication using a remote portal server
- Local portal service
- Portal authentication process
- Portal filtering rules
- Restrictions: Hardware compatibility with portal
- Prerequisites for portal
- Configuring a portal Web server
- Configuring a match rule for URL redirection
- Configuring parameters for a local portal Web service
- Specifying a portal authentication domain
- Specifying a portal authentication domain on an interface
- Specifying a preauthentication IP address pool
- Controlling portal user access
- Configuring an authentication source subnet
- Setting the maximum number of portal users
- Enabling strict-checking on portal authorization information
- Allowing only users with DHCP-assigned IP addresses to pass portal authentication
- Blocking portal users that fail portal authentication
- Configuring the portal fail-permit feature
- Configuring portal detection features
- Configuring portal authentication server detection
- Configuring portal Web server detection
- Configuring portal packet attributes
- Specifying the device ID
- Configuring attributes for RADIUS packets
- Configuring MAC-based quick portal authentication
- Specifying a MAC binding server on an interface
- Setting the user traffic backup threshold
- Enabling portal user login/logout logging
- Display and maintenance commands for portal
- Portal configuration examples
- Example: Configuring re-DHCP portal authentication
- Example: Configuring cross-subnet portal authentication
- Example: Configuring extended direct portal authentication
- Example: Configuring extended re-DHCP portal authentication
- configure dhcp relay
- Example: Configuring extended cross-subnet portal authentication
- Example: Configuring portal server detection and portal user synchronization
- Example: Configuring cross-subnet portal authentication for MPLS L3VPNs
- Example: Configuring direct portal authentication with a preauthentication policy
- Example: Configuring re-DHCP portal authentication with a preauthentication policy
- Example: Configuring direct portal authentication using a local portal Web service
- Example: Configuring MAC-based quick portal authentication
- Troubleshooting portal
- Cannot log out portal users on the access device
- Re-DHCP portal authenticated users cannot log in successfully
- Configuring IPoE
- IPoE session
- IPoE addressing
- Support for MPLS L3VPN
- Support for ITA
- Prerequisites for IPoE
- Configuring dynamic individual users
- Configuring authentication user naming conventions for dynamic individual users
- Configuring passwords for dynamic individual users
- Configuring the maximum number of dynamic IPoE sessions
- Configuring trusted DHCP options for DHCP users
- Configuring trusted source IP addresses for unclassified-IP users
- Enabling dynamic individual users to come online despite the IPoE-NAT collaboration failure
- Configuring static IPoE sessions on an interface
- Configuring global static IPoE sessions
- Configuring passwords for static individual users
- Configuring ISP domains for static individual users
- Configuring interface-leased users
- Configuring L2VPN-leased users
- Configuring service-specific ISP domains
- Configuring the quiet feature for users
- Configuring NAS-Port-Type for an interface
- Configuring NAS-Port-ID formats
- Setting the traffic statistics update timer for IPoE sessions
- Display and maintenance commands for IPoE
- IPoE configuration examples
- Example: Configuring a DHCP user
- Example: Configuring an IPv6-ND-RS user
- Example: Configuring an ARP-based static user
- Example: Configuring subnet-leased users
- Example: Configuring an interface-leased user
- Example: Configuring an L2VPN-leased user
- Example: Configuring a VPN DHCP user
- Example: Configuring online detection
- Troubleshooting IPoE
- Index
manualsdatabase
Your AI-powered manual search engine